Yes, health insurance companies do share information with each other, but only in specific situations and under rules that limit what can move between them. The most common reasons are coordinating payments when you carry more than one policy, verifying what you reported on past applications, and spotting fraud. HIPAA permits these exchanges for payment and healthcare operations without your individual consent, and it requires insurers to share only the minimum information needed for the purpose at hand.1U.S. Department of Health and Human Services. Minimum Necessary Requirement
When You Have Two Plans at Once
The clearest example of insurers talking to each other happens when you’re covered by two health plans at the same time. A typical case: you have coverage through your own employer and you’re also listed as a dependent on your spouse’s plan. Instead of both insurers paying your claim in full, they follow coordination-of-benefits rules to decide which plan pays first (the primary) and which picks up what’s left (the secondary).
Most states base these rules on the NAIC Coordination of Benefits Model Regulation. The primary insurer pays according to its own terms. The secondary insurer then covers remaining eligible costs, with the combined payment capped at 100% of the total allowable expense for the claim.2National Association of Insurance Commissioners. Coordination of Benefits Model Regulation To do its share of the math, the secondary carrier typically requests the Explanation of Benefits from the primary carrier so it knows what was already paid.
For children on both parents’ plans, insurers apply the “birthday rule.” The parent whose birthday falls earlier in the calendar year (month and day, not birth year) has the primary plan for the child. If the parents share a birthday, the plan that has covered that parent longer goes first. A court decree assigning healthcare responsibility after a divorce overrides the birthday rule.2National Association of Insurance Commissioners. Coordination of Benefits Model Regulation
Most of this happens electronically through federally required standard transactions, which is why your secondary insurer often processes a claim within days of the primary insurer’s payment without you lifting a finger.3Centers for Medicare & Medicaid Services. Coordination of Benefits Transactions Basics
Your Application History Through MIB
When you apply for individual coverage, insurers can check a shared database run by MIB Group, Inc. MIB functions as a reporting agency for the insurance industry. When you apply for a policy and disclose health conditions or risky activities, the insurer may file coded summaries with MIB. The next insurer you apply to can pull your file to see whether your new application lines up with what you reported before.4Consumer Financial Protection Bureau. MIB, Inc.
An important distinction: MIB files contain coded flags, not your full medical record. An insurer cannot pull your complete health history from MIB. The database is built to catch inconsistencies between applications, not to serve as a medical chart.
MIB’s role in health insurance has also shrunk since the Affordable Care Act. Because ACA-compliant health plans can’t deny coverage or raise premiums based on pre-existing conditions, the underwriting checks MIB was designed for carry less weight for health coverage. MIB is still heavily used for individual life insurance, disability income, critical illness, and long-term care policies, where medical underwriting continues.4Consumer Financial Protection Bureau. MIB, Inc.
Fraud Detection Networks
Insurers also share data with each other, and with government agencies, to catch fraud. The Healthcare Fraud Prevention Partnership, administered by CMS, is a voluntary public-private partnership that brings private insurers, federal and state agencies, and law enforcement together to compare notes on suspicious billing.5Centers for Medicare & Medicaid Services. HFPP – About the Partnership
The patterns these networks surface are often simple ones: a provider billing two different insurers for the same procedure on the same patient, or a sanctioned provider continuing to bill under a different entity. No single insurer’s data would reveal these on its own; cross-referencing claims across multiple payers makes them visible.
What HIPAA Permits and What It Limits
HIPAA is often described as a wall around your health information. It’s really a framework of permitted and prohibited disclosures. One of its broadest permissions covers “treatment, payment, or healthcare operations.” Under this provision, a covered entity can disclose your protected health information to another covered entity for that entity’s payment activities without asking you first.6eCFR. 45 CFR 164.506 – Uses and Disclosures to Carry Out Treatment, Payment, or Health Care Operations That’s the legal basis for coordination of benefits, prior authorization exchanges, and most routine communication between insurers.
The guardrail is the “minimum necessary” standard. When sharing your information for payment or operations, covered entities must limit what they disclose to the smallest amount reasonably needed.1U.S. Department of Health and Human Services. Minimum Necessary Requirement Your insurer can tell a secondary payer what it paid on a specific claim without handing over your full medical history. This standard applies to nearly every non-treatment disclosure, which means it governs most insurer-to-insurer sharing.
What You Can Do About It
You have more control than most people realize, with real limits. Under HIPAA, you can ask a covered entity to restrict how it uses or discloses your health information for payment or operations purposes. The catch is that the insurer or provider is generally not required to agree.7eCFR. 45 CFR 164.522 – Rights to Request Privacy Protection for Protected Health Information
There is one restriction a provider must honor. If you pay for a healthcare service entirely out of pocket and ask the provider not to disclose that service to your health plan, the provider has to comply, so long as the disclosure isn’t otherwise required by law.7eCFR. 45 CFR 164.522 – Rights to Request Privacy Protection for Protected Health Information If you want a particular visit or test kept off your insurer’s radar, paying cash and invoking this right is how you do it. Once the provider agrees or is required to restrict the information, it can’t be shared with your health plan for payment or operations.
You can also request an accounting of certain disclosures your insurer has made and ask for amendments to inaccurate records. For MIB files specifically, the Fair Credit Reporting Act lets you request a free copy of your file once every 12 months and dispute inaccurate entries, which MIB must investigate at no charge. If an insurer takes adverse action against you based on an MIB report, it must notify you and identify MIB as the source.8Office of the Law Revision Counsel. 15 U.S. Code 1681m – Requirements on Users of Consumer Reports Checking your MIB file before applying for life or disability coverage can catch errors before they cause trouble.
What Doesn’t Automatically Transfer When You Switch Plans
Changing health plans involves less automatic data transfer than many people expect. Your new insurer does not automatically pick up where your old one left off. Your deductible and out-of-pocket maximum typically reset. No federal rule requires the new insurer to credit what you already spent under the old plan, though some employers or insurers voluntarily offer deductible credits during a mid-year switch.
Prior authorizations are a real sore spot. If you’re in the middle of a treatment that your old insurer approved, your new insurer is not automatically bound by that approval. You or your provider will generally need to submit a new prior authorization request. Some states have continuity-of-care laws that require the new insurer to honor existing authorizations for a transition period, but the specifics vary. If you’re switching plans during active treatment, contact your new insurer before the switch to find out what documentation they’ll need.
The 2027 Payer-to-Payer API
How insurers share your data is about to change. The CMS Interoperability and Prior Authorization Final Rule, released in January 2024, requires most health insurers to implement standardized digital interfaces for exchanging patient data, with a key compliance deadline of January 1, 2027.9Centers for Medicare & Medicaid Services. CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F)
The Payer-to-Payer API is the piece that matters most for information sharing between insurers. When you switch plans, your new insurer will be able to electronically request your clinical and claims data from your previous insurer through a standardized interface, and the new payer must incorporate what it receives into your record and make it available through its own systems. Payers can tag the information with metadata showing where it came from, leaving a trail.10Centers for Medicare & Medicaid Services. Payer-to-Payer API
The rule applies to Medicare Advantage plans, Medicaid managed care plans, CHIP plans, and qualified health plans on the ACA marketplace. Once it’s live, switching plans should involve less paperwork and fewer gaps in your care history. It also means your health data will move between insurers more freely than it does today, which makes understanding the privacy limits above more valuable, not less.